What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Closed TopicStart new topic
> [Resolved] Am I clean, Is this computer clean
DA22
post Feb 9 2010, 11:10 AM
Post #1


Authentic Member
**

Group: Authentic Member
Posts: 23
Joined: 2-February 10
Member No.: 90,500
Operating System: WIN XP PRO WIN 7PRO



I am new to this, so please be patient. Before Christmas, everything seamed to be ok. On Christmas the antivirus software stopped updating on 2 computers and I could not get it going on either one. I removed it on both. Then I could not get it installed on either. Mcafee virtual tech crashed on both. I noticed for the first time that CHKDSK was giving errors on both machines that I have never seen on either machine before. Mcafee support cleaned the computer, but could not get their software to install. They blamed Microsoft. Microsoft could not resolve the problems and blamed the drivers. The drivers were the latest and not corrupted and simultaneous failure of the hardware was blamed. Since then I have tested memory and harddrives without any failures and I had the test computer independently tested to verify it was without error.
I noticed that the CHKDSK errors that only occurred on the boot drives and did not resolve with CHKDSK /F on boot, stop when I disconnected the computer from the internet.
I restriped, low format, verify, mount the largest of the offered partitions, format it and reload XP PRO from scratch. I noticed that the computer had already had in it the name of my active workgroup and I did not have to type over the default "workgroup" as I had to do on all previous reloads of XP PRO. I manually check firewall and check to make sure it is installed. In the hour that it was taking to activate XP PRO I rechecked the firewall and it had been disabled and CHKDSK was giving errors.
I disconnected from the internet and repeated the process reconnected and ran your tests. Am I clean? Thank you and if I am clean, what do I do with the other computers? For completeness CHKDSK gives errors on this computer with Windows Essentials disabled and connected to the internet. They stop when I pull the plug from the internet. They did not start until I loaded Windows Essentials on this computer and it was running. After it completed its first clean scan and posted its results, it kept consuming 50% of the processor and I got the first CHKDSK errors at that time. Windows Essentials was not installed on either computer when the problems started.
defogger_disable by jpshortstuff (29.01.10.1)
Log created at 09:27 on 09/02/2010 (DAV34)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-09 10:10:50
Windows 5.1.2600 Service Pack 3
Running: 5t4cqdmg.exe; Driver: C:\DOCUME~1\DAV34\LOCALS~1\Temp\pxtdapob.sys


---- Kernel code sections - GMER 1.0.15 ----

init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xBA9F6510]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2/7/2010 10:07:19 AM
System Uptime: 2/9/2010 8:56:59 AM (2 hours ago)

Motherboard: Gigabyte Technology Co., Ltd. | | 8KNXPU64
Processor: Intel® Pentium® 4 CPU 3.40GHz | Socket 478 | 3407/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 68 GiB total, 60.786 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_8086&DEV_25AD&SUBSYS_50061458&REV_02\3&13C0B0C5&0&EF
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_8086&DEV_25AD&SUBSYS_50061458&REV_02\3&13C0B0C5&0&EF
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1106&DEV_3104&SUBSYS_12340925&REV_51\4&2BA57D2F&0&5AF0
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1106&DEV_3104&SUBSYS_12340925&REV_51\4&2BA57D2F&0&5AF0
Service:

==== System Restore Points ===================

RP1: 2/7/2010 10:19:15 AM - System Checkpoint
RP2: 2/7/2010 11:05:05 AM - Installed DirectX 9.0
RP3: 2/7/2010 11:12:32 AM - Installed TEG-PCITXR 32bit Gigabit PCI Adatper
RP4: 2/7/2010 11:29:33 AM - Software Distribution Service 3.0
RP5: 2/7/2010 11:29:35 AM - Installed Windows XP KB842773.
RP6: 2/7/2010 11:29:53 AM - Installed Windows XP KB892130.
RP7: 2/7/2010 11:42:08 AM - Software Distribution Service 3.0
RP8: 2/7/2010 11:45:12 AM - Installed Windows XP Service Pack 2.
RP9: 2/7/2010 11:55:28 AM - Software Distribution Service 3.0
RP10: 2/7/2010 12:14:09 PM - Software Distribution Service 3.0
RP11: 2/7/2010 12:36:07 PM - Installed Windows XP WgaNotify.
RP12: 2/7/2010 12:38:41 PM - Software Distribution Service 3.0
RP13: 2/7/2010 1:03:11 PM - Software Distribution Service 3.0
RP14: 2/7/2010 1:20:42 PM - Software Distribution Service 3.0
RP15: 2/9/2010 9:07:53 AM - Software Distribution Service 3.0

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
ATI HydraVision
Enable S3 for USB Device
ERUNT 1.1j
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB976098-v2)
Intel® PRO Network Adapters and Drivers
Intel® PROSet
Malwarebytes' Anti-Malware
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Security Essentials
Realtek AC'97 Audio
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
TEG-PCITXR 32bit Gigabit PCI Adatper
Update for Windows Internet Explorer 8 (KB978506)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB978207)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows XP Service Pack 3

==== Event Viewer Messages From Past Week ========

2/9/2010 10:14:23 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the SamSs service.
2/9/2010 10:13:53 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the ProtectedStorage service.
2/7/2010 11:22:00 AM, error: NetBT [4311] - Initialization failed because the driver device could not be created.
2/7/2010 10:19:16 AM, error: System Error [1003] - Error code 000000d1, parameter1 00000002, parameter2 00000007, parameter3 00000001, parameter4 f77f0001.

==== End Of File ===========================

DDS (Ver_09-06-26.01) - NTFSx86
Run by DAV34 at 10:13:19.84 on Tue 02/09/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1510 [GMT -6:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\d\dds.scr

============== Pseudo HJT Report ===============

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [PRONoMgr.exe] c:\program files\intel\ncs\proset\PRONoMgr.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
StartupFolder: c:\docume~1\dav34\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1265563673841
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll

============= SERVICES / DRIVERS ===============

R0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [2004-8-6 242130]

=============== Created Last 30 ================

2010-02-09 08:58 274,288 a------- c:\windows\system32\mucltui.dll
2010-02-09 08:58 215,920 a------- c:\windows\system32\muweb.dll
2010-02-09 08:58 16,736 a------- c:\windows\system32\mucltui.dll.mui
2010-02-07 13:52 <DIR> --d----- c:\docume~1\dav34\applic~1\Malwarebytes
2010-02-07 13:52 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 13:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-07 13:52 19,160 a------- c:\windows\system32\drivers\mbam.sys
2010-02-07 13:52 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 13:20 181,120 -------- c:\windows\system32\MpSigStub.exe
2010-02-07 13:18 <DIR> --d----- c:\program files\Microsoft Security Essentials
2010-02-07 13:16 <DIR> --d----- C:\d
2010-02-07 12:59 <DIR> --dsh--- c:\documents and settings\dav34\IECompatCache
2010-02-07 12:59 <DIR> --dsh--- c:\documents and settings\dav34\PrivacIE
2010-02-07 12:43 <DIR> --d----- c:\windows\system32\scripting
2010-02-07 12:43 <DIR> --d----- c:\windows\system32\en
2010-02-07 12:43 <DIR> --d----- c:\windows\l2schemas
2010-02-07 12:42 <DIR> --d----- c:\windows\network diagnostic
2010-02-07 12:34 <DIR> --dsh--- c:\documents and settings\dav34\IETldCache
2010-02-07 12:30 69,120 -c------ c:\windows\system32\dllcache\iecompat.dll
2010-02-07 12:30 <DIR> --d----- c:\windows\ie8updates
2010-02-07 12:30 11,070,464 -c------ c:\windows\system32\dllcache\ieframe.dll
2010-02-07 12:30 1,985,536 -c------ c:\windows\system32\dllcache\iertutil.dll
2010-02-07 12:30 594,432 -c------ c:\windows\system32\dllcache\msfeeds.dll
2010-02-07 12:30 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2010-02-07 12:30 55,296 -c------ c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-07 12:30 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2010-02-07 12:30 <DIR> -cd-h--- c:\windows\ie8
2010-02-07 12:08 208,896 -c------ c:\windows\system32\dllcache\unregmp2.exe
2010-02-07 12:02 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2010-02-07 12:00 153,088 -c------ c:\windows\system32\dllcache\triedit.dll
2010-02-07 12:00 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2010-02-07 11:55 <DIR> --d----- c:\windows\system32\PreInstall
2010-02-07 11:55 <DIR> --d-h--- c:\windows\$hf_mig$
2010-02-07 11:51 <DIR> --d----- c:\windows\system32\wbem\AutoRecover
2010-02-07 11:47 316,640 a------- c:\windows\WMSysPr9.prx
2010-02-07 11:47 <DIR> --d----- c:\windows\peernet
2010-02-07 11:47 <DIR> --d----- c:\windows\provisioning
2010-02-07 11:46 <DIR> --d----- c:\windows\ServicePackFiles
2010-02-07 11:45 26,144 a------- c:\windows\system32\spupdsvc.exe
2010-02-07 11:44 <DIR> --d----- c:\windows\EHome
2010-02-07 11:41 11,264 -------- c:\windows\system32\spnpinst.exe
2010-02-07 11:41 7,208 -------- c:\windows\system32\secupd.sig
2010-02-07 11:41 4,569 -------- c:\windows\system32\secupd.dat
2010-02-07 11:35 <DIR> --ds---- c:\windows\system32\Microsoft
2010-02-07 11:29 <DIR> --d----- c:\windows\system32\bits
2010-02-07 11:29 438,784 a------- c:\windows\system32\xpob2res.dll
2010-02-07 11:29 354,816 a------- c:\windows\system32\winhttp.dll
2010-02-07 11:29 18,944 a------- c:\windows\system32\qmgrprxy.dll
2010-02-07 11:29 8,192 -------- c:\windows\system32\bitsprx2.dll
2010-02-07 11:29 7,168 -------- c:\windows\system32\bitsprx3.dll
2010-02-07 11:28 217,816 a------- c:\windows\system32\wuaucpl.cpl
2010-02-07 11:28 21,728 a------- c:\windows\system32\wucltui.dll.mui
2010-02-07 11:28 17,632 a------- c:\windows\system32\wuaueng.dll.mui
2010-02-07 11:28 15,072 a------- c:\windows\system32\wuaucpl.cpl.mui
2010-02-07 11:28 15,064 a------- c:\windows\system32\wuapi.dll.mui
2010-02-07 11:27 <DIR> --dsh--- c:\documents and settings\dav34\UserData
2010-02-07 11:27 12,980 a------- c:\windows\system32\wpa.bak
2010-02-07 11:16 22 a------- c:\windows\system32\ati64hlp.stb
2010-02-07 11:12 118,656 a----r-- c:\windows\system32\drivers\Rtnicxp.sys
2010-02-07 11:12 73,728 a----r-- c:\windows\system32\RtNicProp32.dll
2010-02-07 11:12 <DIR> --d----- c:\program files\TRENDware International, Inc
2010-02-07 11:04 516,096 -------- c:\windows\system32\ati2sgag.exe
2010-02-07 11:04 290,816 a----r-- c:\windows\system32\atiiiexx.dll
2010-02-07 11:04 <DIR> --d----- c:\program files\ATI Technologies
2010-02-07 10:28 <DIR> --d----- c:\program files\Realtek Sound Manager
2010-02-07 10:28 <DIR> --d----- c:\program files\AvRack
2010-02-07 10:27 131,072 a----r-- c:\windows\system32\e1000msg.dll
2010-02-07 10:27 118,784 a----r-- c:\windows\system32\Prounstl.exe
2010-02-07 10:27 24,064 a----r-- c:\windows\system32\IntelNic.dll
2010-02-07 10:27 2,725 a----r-- c:\windows\system32\e1000325.din
2010-02-07 10:27 125,952 a----r-- c:\windows\system32\drivers\e1000325.sys
2010-02-07 10:27 <DIR> --d----- c:\program files\Gigabyte
2010-02-07 10:27 306,688 a------- c:\windows\IsUninst.exe
2010-02-07 10:19 <DIR> --dsh--- c:\windows\Installer
2010-02-07 10:19 <DIR> --d----- c:\documents and settings\DAV34
2010-02-07 10:08 8,192 a------- c:\windows\REGLOCS.OLD
2010-02-07 10:06 1,875,968 ac------ c:\windows\system32\dllcache\msir3jp.lex
2010-02-07 10:05 <DIR> --dsh--- c:\documents and settings\all users\DRM
2010-02-07 10:04 <DIR> --d----- c:\program files\common files\MSSoap
2010-02-07 10:03 <DIR> --d-h--- c:\program files\WindowsUpdate
2010-02-07 10:03 <DIR> --d----- c:\program files\Online Services
2010-02-07 10:03 <DIR> --d----- c:\program files\Messenger
2010-02-07 10:03 <DIR> --d----- c:\program files\MSN Gaming Zone
2010-02-07 10:03 <DIR> --d----- c:\program files\Windows NT
2010-02-07 03:55 <DIR> --d--r-- c:\documents and settings\all users\Documents
2010-02-07 03:47 <DIR> --d----- c:\program files\common files\ODBC
2010-02-07 03:47 <DIR> --d----- c:\program files\common files\SpeechEngines

==================== Find3M ====================

2010-02-07 12:45 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-02-07 10:03 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-12-21 23:35 81,920 -------- c:\windows\system32\ieencode.dll
2009-12-21 13:14 916,480 a------- c:\windows\system32\wininet.dll
2009-11-21 09:51 471,552 a------- c:\windows\apppatch\aclayers.dll

============= FINISH: 10:17:13.96 ===============
Hope I did this as stated.

This post has been edited by DA22: Feb 9 2010, 05:51 PM
Go to the top of the page
 
+Quote Post



Closed TopicStart new topic

 


RSS Time is now: 22nd March 2010 - 05:49 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy